Information System Security Officer (ISSO)
Core
Lead security compliance for FedRAMP-authorized cloud environments, ensuring adherence to NIST 800-53, FISMA, and organizational security requirements while managing continuous monitoring and audits.
Role type
Senior Information System Security Officer (ISSO)
Builds
FedRAMP-authorized cloud platforms (Azure, AWS, GCP) serving government stakeholders
Domain
Cybersecurity, Cloud Compliance, Federal Regulations
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
FedRAMP program management, NIST 800-53 controls, FISMA compliance, cloud security (AWS/Azure/GCP), security risk assessment, POA&M management, audit coordination, incident response, security documentation (SSP, SAR), change management (SCR)
Preferred skills
CISSP/CISM/GSLC/CAP certifications, federal agency support experience, GRC tools, AI/automation for compliance, GovCloud/Azure Government experience
Technologies
FedRAMP, NIST SP 800-53, NIST 800-37, FISMA, NIST 800-171, Zero Trust, SIEM, EDR, IAM, AWS, Azure, GCP
Responsibilities
Maintain Authority to Operate (ATO) and lead continuous monitoring activities; coordinate annual assessments, audits, and penetration testing with 3PAOs; conduct security risk assessments and monitor POA&M remediation; manage security communications with federal agencies; maintain FedRAMP documentation (SSP, SAR, etc.); participate in incident investigations and response efforts; partner with engineering teams to integrate compliance into SDLC.
Seniority
Senior, hands-on IC